AI Reserve Developer Documentation

Trust & Disclosures

Security Certifications

Certifications and attestations at every layer of the AI Reserve stack — our own platform, the infrastructure it runs on, the software supply chain, and the model serving providers your traffic can reach. Every mark on this page is the named organization's own certification, stated per that organization's published documentation, and each row links to its source. AI Reserve holds no certifications of its own yet and claims none: our SOC 2 Type II examination is in progress and is stated as exactly that.

Last reviewed: September 9, 2026

How to read this page


A gateway's security story has layers, and mixing them up is how vendors overstate their posture. This page keeps the layers separate: the platform AI Reserve builds and operates, the Google Cloud infrastructure underneath it, the software we run inside our own environment, and the upstream providers that perform model inference under their own terms. Each row states who holds the certification.

  • Held — the named organization holds the certification or attestation, per its own published documentation as of the review date.
  • In-Process — an examination or recertification is underway per the named organization; no report is claimed until one is issued.
  • N/A — not held, not published, or not verified for this matrix as of the review date. It is not a judgment of the organization's security.
Attribution rule. Provider and infrastructure certifications are theirs, not ours — we state them because they cover the layers your data touches, and we never present them as AI Reserve's own. Our own program status is stated in Our own program, honestly, including what we do not yet hold.

Certification matrix


Frameworks shown: SOC 2 (Type II unless a note or footnote states otherwise), ISO/IEC 27001 (information security), ISO/IEC 42001 (AI management), ISO/IEC 27701 (privacy), and HIPAA (a BAA path or configurable eligible workloads — not a certification; a BAA on offer implies the service is HIPAA-eligible). The last column links to each organization's own trust or compliance page. CSA STAR is not shown as a column — no default-routing provider in our registry records it; Google Cloud's and Alibaba Cloud's CSA STAR registrations are recorded in footnotes 2 and 9.

Scope SOC 2 ISO 27001 ISO 42001 ISO 27701 HIPAA Source
AI Reserve platform — built and operated by us
AI Reserve Gateway
Portal, API, and supporting services
In-Process1 N/A1 N/A N/A N/A Trust Center
Infrastructure — where the platform runs
AI Reserve Infrastructure (Google Cloud Platform)
All production infrastructure, region us-east4
2 N/A BAA Compliance Page
Software supply chain — run inside our environment
LiteLLM (BerriAI)
Self-hosted routing engine — never processes customer data as a vendor service
3 In-Process3 N/A N/A N/A Trust Center
Model serving providers — default routing (each provider's own certifications)
OpenAI N/A BAA Security page
Anthropic 4 N/A Configurable Certifications
AWS Bedrock 5 N/A N/A BAA Services in scope
Google Vertex AI 5 N/A BAA Services in scope
Google Gemini API (paid tier) 5 N/A BAA Compliance controls · API terms
xAI N/A N/A N/A N/A6 Security FAQ
Perplexity N/A N/A N/A N/A Privacy & security
Mistral AI N/A N/A Certifications
Together AI N/A N/A N/A Eligible Trust Center
Fireworks AI N/A N/A N/A Eligible Trust Center
DeepInfra Type I7 N/A N/A Eligible Trust Center
Novita AI N/A N/A N/A N/A Trust Center
Baseten N/A N/A N/A Eligible Trust Center
OpenRouter N/A8 N/A N/A N/A N/A Privacy docs

This page tracks certifications only. The authoritative per-provider data-handling matrix — training posture, retention window, processing region, and DPA role — is the Provider Data Handling page. Media-generation and dedicated GPU-deploy routes (fal.ai, Hugging Face Inference Endpoints, WaveSpeedAI, MuleRouter) are documented there as well; no formal attestations for them have been verified into our reviewed registry, so they carry no marks here.

Our own program, stated honestly


AI Reserve's SOC 2 Type II examination is in progress — Type I first, with the Type II observation window to follow — and no report has been issued yet, so we do not claim our own certification anywhere. What already operates today: the control set is implemented and documented, compliance automation (Vanta) runs continuous checks against the live environment, and our build pipeline enforces the public claims registries on every change — a page like this one cannot drift from what the code actually does without failing CI.

Once a report is issued, our Data Processing Agreement provides that a current report is accepted in lieu of an audit of covered controls; until then we complete reasonable written security questionnaires. Reports, questionnaires, and documentation requests are handled through the Trust Center or your AI Reserve point of contact.

Sources & footnotes


Provider certifications are reviewed against each provider's published documentation (linked per row). Where a provider has a profile in our provider-trust registry — the same registry that powers the data-handling matrix and the in-product provider trust panels — per-provider review dates are maintained there; rows without a registry profile (OpenRouter, ByteDance) state their basis in the footnotes. This page is regenerated to the privacy site with every production deploy.

  1. AI Reserve's SOC 2 Type II examination is in progress (Type I first, then the Type II observation window); no report has been issued and no completion date is promised here. We have not enrolled in an ISO 27001 certification program; the infrastructure layer's ISO 27001 is Google's (row below). See the overview's compliance section.
  2. Google Cloud's certifications for the infrastructure layer — not AI Reserve's own. Google Cloud holds SOC 1/2/3 and ISO/IEC 27001, 27017, 27018, and 27701 for in-scope services and offers HIPAA BAAs (our registry records the SOC attestations without pinning the report type — footnote 5); Google additionally documents further programs (including CSA STAR and FedRAMP High for applicable services) on its compliance offerings page — those are not marked in the matrix because our reviewed registry does not yet track them: cloud.google.com/security/compliance/offerings. All AI Reserve production infrastructure runs in Google Cloud region us-east4; physical security of the facilities is delegated to Google and evidenced by these certifications. AI Reserve personnel have no physical access to any data center.
  3. LiteLLM is the open-source routing engine inside our gateway. We self-host it inside our own Google Cloud project: BerriAI (the maintainer) never receives or processes customer data, so this row is a software supply-chain attestation, not a data-processor certification. LiteLLM's updated SOC 2 Type II report was issued on September 8, 2026 (report announcement), completing the recertification with Vanta and an independent auditor announced March 2026 (recertification announcement); the ISO 27001 recertification from that announcement remains in process. Status per its trust center at trust.litellm.ai.
  4. Anthropic holds SOC 2 Type I and Type II; HIPAA is configurable for eligible workloads per Anthropic's documentation.
  5. AWS and Google Cloud hold SOC 1, SOC 2, and SOC 3, plus ISO/IEC 27017 and 27018 (cloud and PII controls) beyond the columns shown. Bedrock and Vertex AI are HIPAA-eligible services with BAA paths via AWS and Google Cloud respectively; processing is pinned to our configured regions. Our provider registry records these SOC attestations without pinning the report type, so the checks on these rows are not a Type II claim by us — the type designation is whatever the vendor's current report states. Gemini API paid-tier prompts and responses are processed under Google's Data Processing Addendum for Products Where Google is a Data Processor, per the linked Gemini API Additional Terms; the marks on that row are Google's platform attestations as recorded in our registry, which tracks the Gemini paid tier alongside Vertex AI.
  6. xAI documents a BAA inquiry path but not a standing HIPAA-eligible offering, per its enterprise security FAQ.
  7. DeepInfra's SOC 2 attestation is Type I, per its trust center.
  8. OpenRouter is a routing aggregator on our default paths for a small set of models; no formal security attestation for it has been verified into our reviewed registry as of the review date. Its no-training posture, metadata-only logging default, and per-route downstream endpoints are documented on the data-handling page.
  9. Alibaba Cloud's platform certification portfolio (SOC 2, ISO 27001/17/18/701, CSA STAR) per its trust center; our registry records the SOC 2 attestation without pinning the report type. The operator is under PRC jurisdiction, which is why the PRC-server consent gate applies regardless of certifications.
  10. No formal security attestations verified for this matrix as of the review date. Traffic reaches these providers only as the named consent gate permits — see the section introduction for how each gate defaults.

Questions, or need a report under NDA: contact your AI Reserve point of contact, product@aireserve.com, or the Trust Center.